The product
Your evidence, collected while you sleep
Step one
Connect it, then forget about it
Read-only credentials to the systems you already pay for. Trusterio reads them on a schedule and never writes to any of them — which is also why it will not pretend to have revoked anything.
- AWS
- accounts, buckets, keys, security groups
- Azure
- subscriptions, storage, network rules
- Entra ID
- accounts, MFA, admin roles, joiners and leavers
- Google Workspace
- accounts, two-step, sharing settings
- GitHub
- repositories, branch protection, reviewers
- Okta
- applications, factors, sessions
- Intune
- devices, encryption, patch level
- Jamf
- Macs, FileVault, OS version
- Kandji
- Macs, blueprints, enforcement
- Jira
- change tickets, approvals, releases
- Slack
- channels, retention, guest access
- Personio
- employees, start and end dates
- HiBob
- employees, start and end dates
- BambooHR
- employees, start and end dates
Each connection reports when it was last read and what it found. A connection that has gone quiet says so on the dashboard, rather than silently reporting yesterday.
Step two
Controls that test themselves
Every control has a test, and every test has a schedule. The result is a status you did not type in — and a history showing how long it has been true.
Untested is not passing
A control whose test has not run recently is reported as unknown, and unknown lowers your score. Rounding up is how a dashboard becomes a decoration.
One control, many frameworks
Requirements from ISO 27001, SOC 2, NIS2 and DORA point at the same control. Collect the evidence once; it counts wherever it applies.
An exclusion is on the record
Decide a requirement does not apply and the score moves — with your reason attached to it, visible beside the number it changed.
Step three
A short list, with names on it
Findings come out of readings, not out of a workshop. Each one gets an owner and a date, and closing it means the next reading agrees — not that somebody ticked a box.
- Owners, not a queueA finding with nobody on it is a finding nobody will do. Every one carries a person and a date.
- Closed by observationMarking a finding fixed does not close it. The next reading of the system does.
- Risk that argues backA risk you reduced on paper is reported at its inherent score until the control behind it is actually passing.
The rest of it
The three spreadsheets you can throw away
The parts of compliance that usually live somewhere else entirely, in the same place as the evidence that backs them.
The GDPR Article 30 record
Every processing activity with its purpose, legal basis, categories, recipients and retention — and checked against what your Trust Center says you hold. The two cannot quietly disagree.
Joiners and leavers
Read from your HR system rather than typed in. A leaver stays open until a later reading of every directory reports the account gone.
Security questionnaires
Answers drafted from what you have already published, with the sources attached, and checked against them before anybody sees a draft. Nothing is invented.
Fourteen days. The whole thing.
No card, no sales call, no demo you have to sit through. Your data stays in the EU.